WannaCry Ransomware: Analysis of Infection, Persistence, Recovery Prevention and Propagation Mechanisms

In recent years, we have been experiencing fast proliferation of different types of ransomware targeting home users, companies and even critical telecommunications infrastructure elements. Modern day ransomware relies on sophisticated infection, persistence and recovery prevention mechanisms. Some re...

Full description

Saved in:
Bibliographic Details
Published inJournal of Telecommunications and Information Technology Vol. 1; no. 2019; pp. 113 - 124
Main Authors Akbanov, Maxat, Vassilakis, Vassilios G., Logothetis, Michael D.
Format Journal Article
LanguageEnglish
Published Warsaw Instytut Lacznosci - Panstwowy Instytut Badawczy (National Institute of Telecommunications) 2019
National Institute of Telecommunications
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:In recent years, we have been experiencing fast proliferation of different types of ransomware targeting home users, companies and even critical telecommunications infrastructure elements. Modern day ransomware relies on sophisticated infection, persistence and recovery prevention mechanisms. Some recent examples that received significant attention include WannaCry, Petya and BadRabbit. To design and develop appropriate defense mechanisms, it is important to understand the characteristics and the behavior of different types of ransomware. Dynamic analysis techniques are typically used to achieve that purpose, where the malicious binaries are executed in a controlled environment and are then observed. In this work, the dynamic analysis results focusing on the infamous WannaCry ransomware are presented. In particular, WannaCry is examined, during its execution in a purpose-built virtual lab environment, in order to analyze its infection, persistence, recovery prevention and propagation mechanisms. The results obtained may be used for developing appropriate detection and defense solutions for WannaCry and other ransomware families that exhibit similar behaviors
Bibliography:ObjectType-Article-1
SourceType-Scholarly Journals-1
ObjectType-Feature-2
content type line 14
ISSN:1509-4553
1899-8852
DOI:10.26636/jtit.2019.130218